MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc654ac0e604bffa6762f50c4fbc1f216607af6be502ad9e6baf2b5895ba367a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc654ac0e604bffa6762f50c4fbc1f216607af6be502ad9e6baf2b5895ba367a
SHA3-384 hash: dd2b73aa925410f5c2f285378dc535b1955c2b9cff335f33fbc00f3772d0542e2977cb9571df167b4a29529aacaa4f2d
SHA1 hash: 606f8923a779a6721427f69dc59349762cc7fd26
MD5 hash: 18e3f5db7c5ef080c350f3e88744b82d
humanhash: mountain-delaware-kilo-steak
File name:T9827826788.IMG
Download: download sample
Signature AgentTesla
File size:1'245'184 bytes
First seen:2020-06-11 11:16:34 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:xaUPSH6VEJD6Lp4CkdrjvwKDR1ty56ZN3Amq8xdiwT:xaUE6VEt6MfzDRGWNQmq8/iw
TLSH 53459D2772826458D83E423614BAAFC2A6373F8539B1571FB1AE73184F3329F376550A
Reporter abuse_ch
Tags:AgentTesla img


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: out03.mse.messcube.it
Sending IP: 62.77.35.113
From: Giovanni Traversa <giovanni@tgprogidatraversa.it>
Subject: Aw: WG: 100pcs/ T6961008100800000
Attachment: T9827826788.IMG (contains "T8927628728.exe")

AgentTesla SMTP exfil server:
smtp.rebajitrading.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-06-11 08:41:43 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

img dc654ac0e604bffa6762f50c4fbc1f216607af6be502ad9e6baf2b5895ba367a

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments